Leadership Council Teleconference - 2010-09-01
Minutes approved September 15, 2010
Kantara Leadership Council Teleconference
Date and Time
- Date: Wednesday, September 1, 2010
- Time: 3pm PDT | 6pm EDT | 22:00 UTC (Time Chart)
- Teleconference Options:
- Skype: +9900827043671716
- US Dial-In: +1-201-793-9022 | Room Code: 3671716
NOTES:
- Skype calls are toll-free, and you do NOT need to enter the Room Code.
- International Numbers: http://kantara.atlassian.net/wiki/display/GI/Telco+Bridge+Info
- Contact the Chair if you cannot use Skype and need a toll-free phone number (US or international)
Attendees
- Voting:
- User-Managed Access: Eve Maler
- ULX: Phillipe Clement
- Federation Interoperability: John Bradley
- Japan WG: Toshihiro Suzuki
- eGov: Colin Wallis
- Privacy and Public Policy: Abbie Barbir
- Non-Voting:
- Identity Community Update: J. Trent Adams
- Map the Gap: J. Trent Adams
- Staff: Joni Brennan
- Staff: Dervla O'Reilly
- Guest: Drummond Reed
Apologies
- Consumer ID: Bob Pinheiro
Agenda
- Roll Call for Quorum Determination
- Approval of prior meeting minutes
- OIX Presentation - Drummond Reed
- Reminder: Quarterly Reports
- Call for Group Leaders to add 2010-Q2 Report and to back-fill prior reports
- Add Reports to: Quarterly Reports
- Using Report Template: Quarterly Report Template
- Call for Paris Meeting Agendas
- Proposal: Creation of a fellowship program supporting independent volunteers.
- Action Item Reviews:
- NASPO: LC Members interested in actively moving this work forward are asked to formalize a proposal and bring it to the LC for consideration.
- United Identities: Colin will send the presentation around on the LC list, soliciting responses of interest.
- AOB
Minutes
- Roll Call for Quorum Determination
- 6 voting members, quorum reached
- Approval of prior meeting minutes
- MOTION: To approve the minutes as recorded for the Leadership Council Teleconference on 2010-08-04.
- Moved by Colin, Motion Carried
- Open Identity Exchange (OIX) Presentation
- Introductory Notes:
- Presented by Drummond Reed and John Bradley
- ICF loaned Drummond to help bootstrap OIX
- Drummond stepped down as ED of OIX after Catalyst, returning to ICF
- Drummond is speaking as volunteer continuing to support the project
- Don Thibeau now acting ED
- John Bradley joined OIX as a volunteer Technical Advisor
- General Overview:
- OIX is primarily a registry, or "listing", of certified services (IdPs and RPs)
- OIX "lists" operational trust frameworks
- OIX and Kantara are symbiotic (as defined by the recent press release)
- Kantara is one producer (among others) of frameworks that are listed and assessed against.
- "Operational Certification" of each framework is defined by the framework producer (a.k.a. "framework authority")
- OIX does not offer a certification service itself, it is a listing service on behalf of the "framework authority" (e.g. GSA/ICAM, Kantara, etc.)
- OIX uses a "Rules & Tools" model to identify the difference between "process" (OIX) and "mechanism" (e.g. certification mechanism)
- OIX builds on top of "Federation Operator Guidelines" that are both "Rules Based" and "Operational Based"
- The term "profiles" is used to describe how a "framework authority" needs a specific technology to be implemented in order to be certified (and subsequently "listed" by OIX)
- OIX is still solidifying methods for how "profiles" are created (e.g. by Kantara) and submitted to OIX for "listing"
- OIX listings are technology neutral, not promoting any one specific technology.
- There is an understood US-bias in many of the OIX foundational documents (many based on profiles from the US Gov), they are looking to expand further.
- OIX carries some indemnifcation insurance
- Q: If OIX "lists", but doesn't "certify", what is the actual process for getting "listed"?
- A: This is still being defined, but the rough process is being formalized now.
- Basic steps in "listing" a hypothetical new trust framework:
- Example: LinkedOrg wants to submit a Trust Framework and have IdPs certified against it listed by OIX
- For LinkedOrg to be a Trust Framework Authority, OIX requires:
- they be a legal entity
- they must be an OIX Member
- LinkedOrg puts together a "Trust Framework Specification" comprised of:
- Starting with with an "Implementation Profile" of Kantara IAF and...
- ... they add their own rules to it (e.g. a Privacy Profile)
- They then define the same OpenID Profile used by ICAM for LOA 1.
- To become an OIX Listed Trust Framework, OIX must verigy they are "compliant" by OIX General Counsel (currently Scott David):
- Verify that it is an authetnic submission (i.e. all appropriate forms are filled out and steps followed) from an authentic member (i.e. an OIX member in good standing)
- Verify that it meets all the requirements of the "OIX Trust Framework Requirements Document"
- This is a proforma evaluation to ensure steps are followed, nothing about the contained details.
- Verfification includes:
- how assessors will do their job when certifying services for the proposed Trust Framework
- that the submitted framework meets minimum bar from the "Principles of Openness" whitepaper:
- The Trust Framework Authority must self-certify they agree to the principles.
- Assesors for the LinkedOrg "Trust Framework Specification" must:
- submit a "Trust Framework Participant Form"
- meet requirements set out in the submitted "Trust Framework Specification"
- They go through the Assesor Qualification Process to be "Listed"
- They must be OIX Members (or a Kantara-certified assesor)
- Participants (e.g. IDPs and RPs, etc.) go through a similar process to be "Listed"
- They must also be OIX Members
- NOTE: Kantara certified assesors are automatically accepted
- Operation:
- Listings will be queried using SAML-based signed metadata
- Security will be matched to LOA (e.g. higher levels may require)
- Much of this is still being worked out, in conjunction with input from the Fed Interop
- Introductory Notes:
- Reminder: Quarterly Reports
- Call for Group Leaders to add 2010-Q2 Report and to back-fill prior reports
- Add Reports to: Quarterly Reports
- Using Report Template: Quarterly Report Template
- Call for Paris Meeting Agendas
- Deadline for early-bird registration: September 17
- Proposal: Creation of a fellowship program supporting independent volunteers.
- Action Item Reviews:
- NASPO: LC Members interested in actively moving this work forward are asked to formalize a proposal and bring it to the LC for consideration.
- United Identities: Colin will send the presentation around on the LC list, soliciting responses of interest.
- Meeting adjourned at 23:30
Next Teleconference
- Date: Wednesday, September 15, 2010
- Time: 9am PDT | 12pm EDT | 16:00 UTC (Time Chart)
- Teleconference Options:
- Skype: +9900827043671716
- US Dial-In: +1-201-793-9022 | Room Code: 3671716
NOTES:
- Skype calls are toll-free, and you do NOT need to enter the Room Code.
- International Numbers: http://kantara.atlassian.net/wiki/display/GI/Telco+Bridge+Info
- Contact the Chair if you cannot use Skype and need a toll-free phone number (US or international)